IP purity scoring

One 0–100 score, higher is better. This page describes the current scoring model 2.3; any rule change bumps the version, and result pages show which version was used.

Two ground rules

Five dimensions and weights

DimensionWeightWhat it looks at
Reputation32%Blocklists, threat intelligence, mail reputation
Abuse history27%Fraud and abuse reports
Anonymization23%VPN, proxy, Tor or datacenter exit
Geo agreement10%Whether geolocation databases agree (agreement, not accuracy)
Port exposure8%Open proxy, remote-admin or database ports

When a score is given

All of the following must hold; otherwise the page says "not scored" and explains why:

Opening the home page runs a basic check that does not send your IP to third-party intelligence sources, so it may not produce a score; "run deep check" fills in the rest.

Caps

These cap the score. If several apply, the lowest wins and all are listed:

ConditionMaximum
Hard threat-intel hit (criminal-controlled ranges, active C2, …)19
Tor exit0
Residential proxy54
VPN54
Datacenter network (network-type confidence ≥ 0.5)54

Model 2.3 sets Tor exits to 0: their purpose is to hide the origin, so a detected Tor exit scores 0 and lands in "Severe". Model 2.2 lowered the datacenter and VPN cap from 69 to 54, the same band as residential proxies, because most platforms scrutinize datacenter exits noticeably harder. It does not mean these addresses are malicious. IP type (residential, datacenter, …) only acts through the cap and is never deducted again in a dimension: one fact is used once.

Hard intelligence and soft signals

Port exposure

Only the worst category counts: proxy ports (1080, 3128, 8080, …) −40, remote admin (23, 3389, 5900) −25, databases (3306, 5432, 6379, …) −15, other ports −10; each extra category adds 5, capped at 60 in total. CVEs are not scored, since that would systematically penalize people who self-host.

Grade bands

ScoreGrade
85–100Clean
70–84Fairly clean
55–69Check
40–54Elevated risk
20–39High risk
0–19Severe

What is not scored

WebRTC leaks, DNS leaks, identity consistency and dual-stack exits can only be tested by the IP's holder and describe device setup rather than the IP, so they are shown as optional tests outside the score. Routing, registry details and some shadow sources are shown for information only.

Where the data comes from: sources.

Look up an IP